When Microsoft rejects your email, it is almost always one of five causes. Work through them in this order, because each one is faster to check than the next and each one rules out a whole class of problems. The rejection message will usually include a sub-code, but the five causes below cover 95 percent of cases.
Microsoft rejects unauthenticated mail. Check that SPF lists every sending server, DKIM is signing on the From domain, and DMARC is present. The DMARC checker runs all three in one pass. If any record is missing or wrong, that is your cause and the fix is a DNS change, not a code change. For the exact records, the SPF, DKIM and DMARC guide covers each one. If your SPF has more than ten DNS lookups, that is a separate failure mode covered in the SPF lookup limit guide.
Even with clean records, a listed IP gets rejected. The IP blacklist checker tests the sending IP against nine major lists. If you are listed, the Spamhaus delisting guide covers the request. Delisting only sticks if the underlying cause is fixed first. If the IP is not listed but the domain is new, the problem is reputation, not blocklisting.
A fresh domain sending at volume to Microsoft is the most common cause of silent rejection. Microsoft builds reputation slowly and punishes sudden volume from unknown domains. If you are doing cold outreach, warm up the sending domain before scaling. A new domain should ramp over weeks, not days. If the domain has been sending for months and suddenly started getting rejected, the problem is likely a content or list quality change, not the domain age.
If authentication, IP, and reputation are all clean, the problem is behavior: a high bounce rate, content that does not match the domain, or a list full of stale addresses. Validate the list before sending and keep volume gradual. Microsoft also weighs engagement signals: if recipients are not opening or replying, Microsoft lowers your deliverability score.
Microsoft periodically tightens its spam filters. If you were delivering fine and suddenly started getting rejected with no changes on your side, check the Outlook deliverability guide for the current requirements. Microsoft has been known to require DMARC on the From domain specifically, not just the sending domain. The DMARC record guide covers the exact syntax.
The free deliverability checker runs all of these signals at once and points at the first thing to fix.
Want this checked automatically every day? Inboxproof Pro monitors your domain around the clock and alerts you the moment a record breaks or an IP gets listed. See pricing →